STRM Users Guide
Editing a Sentry
73
Step 4
Update values for the parameters, as necessary:
a
If you are editing a Security/Policy sentry:
b
If you are editing a Behavior, Anomaly, or Threshold sentry:
Table 4-20
Edit Security/Policy Sentry
Parameter
Description
Name
Specify a name for this sentry.
Description
Specify a description for this sentry. This description appears as
an annotation in the Offense Manager if this sentry causes an
offense to generate.
Minimum number
of flows before
emitting events
Specify the minimum number of times, in flows, this activity must
occur before an event generates.
Delay between
emitting events
Specify the number of seconds, after the first occurrence of this
event, before the next occurrence of this event. For example, if
you set the value to 3, an event generates after three seconds of
the first instance of the event.
Maximum emitted
events per IP
Specify the maximum number of times you wish this event to
generate per IP address. For example, if you set the maximum
alerts to 2, only two alerts generate per event.
Is Enabled
Select the check box to enable this sentry. Clear the check box to
disable the sentry.
Options
Select the check box if you wish this event to be included with
other events to create an offense. Use the Address to mark as
the target drop-down list box to identify if you wish the destination
or source IP address to be used as the target.
Note:
This option only appears for a Security/Policy sentry.
Permissions
Specify the users you wish to allow access to edit this sentry.
Package
Using the drop-down list box, select the sentry package you wish
to apply to this sentry. To edit an existing package, click
Edit
or
to create a new package, click
Create New
.
QRL
Specifies the details of the current view for this sentry.
Table 4-21
Edit Behavior, Anomaly, or Threshold Sentry
Parameter
Description
Name
Specify a name for this sentry.
Description
Specify a description for this sentry. This description appears as
an annotation in the Offense Manager if this sentry causes an
offense to generate.
Minimum number
of flows before
alert
Specify the minimum number intervals this activity must occur
before an alert generates.
Delay between
alerts
Specify the number of intervals after the first occurrence of this
event, before the next occurrence of this event.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......